2020-07-30 01:50:30 +02:00
|
|
|
// Copyright © 2020 Metabolist. All rights reserved.
|
|
|
|
|
|
|
|
import Foundation
|
2020-09-04 02:54:05 +02:00
|
|
|
import Keychain
|
2020-07-30 01:50:30 +02:00
|
|
|
|
2020-08-31 12:21:01 +02:00
|
|
|
public protocol SecretsStorable {
|
2020-07-30 01:50:30 +02:00
|
|
|
var dataStoredInSecrets: Data { get }
|
|
|
|
static func fromDataStoredInSecrets(_ data: Data) throws -> Self
|
|
|
|
}
|
|
|
|
|
|
|
|
enum SecretsStorableError: Error {
|
|
|
|
case conversionFromDataStoredInSecrets(Data)
|
|
|
|
}
|
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
public struct Secrets {
|
2020-08-31 12:21:01 +02:00
|
|
|
public let identityID: UUID
|
2020-09-04 02:54:05 +02:00
|
|
|
private let keychain: Keychain.Type
|
2020-07-30 01:50:30 +02:00
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
public init(identityID: UUID, keychain: Keychain.Type) {
|
2020-08-09 04:52:41 +02:00
|
|
|
self.identityID = identityID
|
2020-09-04 02:54:05 +02:00
|
|
|
self.keychain = keychain
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
public extension Secrets {
|
2020-08-09 04:52:41 +02:00
|
|
|
enum Item: String, CaseIterable {
|
2020-08-12 09:24:39 +02:00
|
|
|
case clientID
|
|
|
|
case clientSecret
|
|
|
|
case accessToken
|
|
|
|
case pushKey
|
|
|
|
case pushAuth
|
2020-09-04 08:12:06 +02:00
|
|
|
case databasePassphrase
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-09-04 08:12:06 +02:00
|
|
|
public enum SecretsError: Error {
|
2020-08-14 05:40:46 +02:00
|
|
|
case itemAbsent
|
|
|
|
}
|
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
extension Secrets.Item {
|
2020-08-14 03:59:17 +02:00
|
|
|
enum Kind {
|
|
|
|
case genericPassword
|
|
|
|
case key
|
|
|
|
}
|
|
|
|
|
|
|
|
var kind: Kind {
|
|
|
|
switch self {
|
|
|
|
case .pushKey: return .key
|
|
|
|
default: return .genericPassword
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
public extension Secrets {
|
2020-09-04 08:12:06 +02:00
|
|
|
static func setUnscoped(_ data: SecretsStorable, forItem item: Item, keychain: Keychain.Type) throws {
|
|
|
|
try keychain.setGenericPassword(
|
|
|
|
data: data.dataStoredInSecrets,
|
|
|
|
forAccount: item.rawValue,
|
|
|
|
service: keychainServiceName)
|
|
|
|
}
|
|
|
|
|
|
|
|
static func unscopedItem<T: SecretsStorable>(_ item: Item, keychain: Keychain.Type) throws -> T {
|
|
|
|
guard let data = try keychain.getGenericPassword(
|
|
|
|
account: item.rawValue,
|
|
|
|
service: Self.keychainServiceName) else {
|
|
|
|
throw SecretsError.itemAbsent
|
|
|
|
}
|
|
|
|
|
|
|
|
return try T.fromDataStoredInSecrets(data)
|
|
|
|
}
|
|
|
|
|
2020-08-09 04:52:41 +02:00
|
|
|
func set(_ data: SecretsStorable, forItem item: Item) throws {
|
2020-09-04 02:54:05 +02:00
|
|
|
try keychain.setGenericPassword(
|
2020-08-12 09:24:39 +02:00
|
|
|
data: data.dataStoredInSecrets,
|
2020-09-04 08:12:06 +02:00
|
|
|
forAccount: scopedKey(item: item),
|
2020-08-12 09:24:39 +02:00
|
|
|
service: Self.keychainServiceName)
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
|
|
|
|
2020-08-14 05:40:46 +02:00
|
|
|
func item<T: SecretsStorable>(_ item: Item) throws -> T {
|
2020-09-04 02:54:05 +02:00
|
|
|
guard let data = try keychain.getGenericPassword(
|
2020-09-04 08:12:06 +02:00
|
|
|
account: scopedKey(item: item),
|
2020-08-12 09:24:39 +02:00
|
|
|
service: Self.keychainServiceName) else {
|
2020-09-04 08:12:06 +02:00
|
|
|
throw SecretsError.itemAbsent
|
2020-08-09 03:29:05 +02:00
|
|
|
}
|
2020-07-30 01:50:30 +02:00
|
|
|
|
|
|
|
return try T.fromDataStoredInSecrets(data)
|
|
|
|
}
|
|
|
|
|
2020-08-09 04:52:41 +02:00
|
|
|
func deleteAllItems() throws {
|
2020-09-04 02:54:05 +02:00
|
|
|
for item in Secrets.Item.allCases {
|
2020-08-14 03:59:17 +02:00
|
|
|
switch item.kind {
|
|
|
|
case .genericPassword:
|
2020-09-04 02:54:05 +02:00
|
|
|
try keychain.deleteGenericPassword(
|
2020-09-04 08:12:06 +02:00
|
|
|
account: scopedKey(item: item),
|
2020-08-14 03:59:17 +02:00
|
|
|
service: Self.keychainServiceName)
|
|
|
|
case .key:
|
2020-09-04 08:12:06 +02:00
|
|
|
try keychain.deleteKey(applicationTag: scopedKey(item: item))
|
2020-08-14 03:59:17 +02:00
|
|
|
}
|
2020-08-09 04:52:41 +02:00
|
|
|
}
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
2020-08-12 09:24:39 +02:00
|
|
|
|
|
|
|
func generatePushKeyAndReturnPublicKey() throws -> Data {
|
2020-09-04 02:54:05 +02:00
|
|
|
try keychain.generateKeyAndReturnPublicKey(
|
2020-09-04 08:12:06 +02:00
|
|
|
applicationTag: scopedKey(item: .pushKey),
|
2020-08-13 12:18:21 +02:00
|
|
|
attributes: PushKey.attributes)
|
2020-08-12 09:24:39 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func getPushKey() throws -> Data? {
|
2020-09-04 02:54:05 +02:00
|
|
|
try keychain.getPrivateKey(
|
2020-09-04 08:12:06 +02:00
|
|
|
applicationTag: scopedKey(item: .pushKey),
|
2020-08-13 12:18:21 +02:00
|
|
|
attributes: PushKey.attributes)
|
2020-08-12 09:24:39 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func generatePushAuth() throws -> Data {
|
2020-08-13 12:18:21 +02:00
|
|
|
var bytes = [UInt8](repeating: 0, count: PushKey.authLength)
|
2020-08-12 09:24:39 +02:00
|
|
|
|
2020-08-13 12:18:21 +02:00
|
|
|
_ = SecRandomCopyBytes(kSecRandomDefault, PushKey.authLength, &bytes)
|
2020-08-12 09:24:39 +02:00
|
|
|
|
|
|
|
let pushAuth = Data(bytes)
|
|
|
|
|
|
|
|
try set(pushAuth, forItem: .pushAuth)
|
|
|
|
|
|
|
|
return pushAuth
|
|
|
|
}
|
|
|
|
|
|
|
|
func getPushAuth() throws -> Data? {
|
|
|
|
try item(.pushAuth)
|
|
|
|
}
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
|
|
|
|
2020-09-04 02:54:05 +02:00
|
|
|
private extension Secrets {
|
2020-08-12 09:24:39 +02:00
|
|
|
static let keychainServiceName = "com.metabolist.metatext"
|
|
|
|
|
2020-09-04 08:12:06 +02:00
|
|
|
func scopedKey(item: Item) -> String {
|
2020-08-08 01:19:13 +02:00
|
|
|
identityID.uuidString + "." + item.rawValue
|
2020-07-30 01:50:30 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
extension Data: SecretsStorable {
|
2020-08-31 12:21:01 +02:00
|
|
|
public var dataStoredInSecrets: Data { self }
|
2020-07-30 01:50:30 +02:00
|
|
|
|
2020-08-31 12:21:01 +02:00
|
|
|
public static func fromDataStoredInSecrets(_ data: Data) throws -> Data {
|
2020-07-30 01:50:30 +02:00
|
|
|
data
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
extension String: SecretsStorable {
|
2020-08-31 12:21:01 +02:00
|
|
|
public var dataStoredInSecrets: Data { Data(utf8) }
|
2020-07-30 01:50:30 +02:00
|
|
|
|
2020-08-31 12:21:01 +02:00
|
|
|
public static func fromDataStoredInSecrets(_ data: Data) throws -> String {
|
2020-07-30 01:50:30 +02:00
|
|
|
guard let string = String(data: data, encoding: .utf8) else {
|
|
|
|
throw SecretsStorableError.conversionFromDataStoredInSecrets(data)
|
|
|
|
}
|
|
|
|
|
|
|
|
return string
|
|
|
|
}
|
|
|
|
}
|
2020-08-13 12:18:21 +02:00
|
|
|
|
2020-08-31 12:21:01 +02:00
|
|
|
private struct PushKey {
|
2020-08-13 12:18:21 +02:00
|
|
|
static let authLength = 16
|
|
|
|
static let sizeInBits = 256
|
|
|
|
static let attributes: [String: Any] = [
|
|
|
|
kSecAttrKeyType as String: kSecAttrKeyTypeECSECPrimeRandom,
|
|
|
|
kSecAttrKeySizeInBits as String: sizeInBits]
|
|
|
|
}
|